Getting into your account, and getting back in
An account that holds a balance and a verified identity is worth more to an attacker than a social media login. The protections that matter are unglamorous, and almost all of them have to be arranged before anything goes wrong.
- A verified identityLicensed platforms must verify identity and age under the 2025 Act, so an account carries documents as well as a balance.
- Money held for youLicensed platforms must hold user funds in segregated accounts and ensure refundability, which makes account control a financial question.
- A limit configurationSelf-exclusion, time limits and deposit limits are mandatory features. Whoever controls the login can change them.
- A complaint routeGrievance redressal is required of licensed platforms, and the Act establishes an appellate tribunal. Both need you to prove who you are.
What you are protecting
Why this account is a harder target to lose than most
Losing access to a gaming account is unlike losing access to an ordinary service in two respects. The first is that there is money on the other side of the login. The second, and less obvious, is that regaining access requires satisfying a platform that is under legal obligations about identity, which means the recovery process is deliberately not casual.
That second point cuts both ways. It is why account takeover is harder than on a service with no verification requirement, and it is also why recovery is slower. A platform that must verify identity and age under the 2025 Act cannot simply accept an email request to move access to a new address, because doing so would undermine the obligation.
The attack that actually happens
The common failure is not a sophisticated intrusion. It is credential reuse: a password used on a gaming account that was also used somewhere that suffered a breach, combined with the absence of a second factor. The attacker does not need to break the platform, only to try a known password against a known email address.
The second common failure is a recovery channel that is weaker than the account. If the account is protected by a strong password and a second factor, but the recovery route is an email address protected by a password from 2015, the real strength of the account is that email password.
This desk does not publish any operator's specific security features, session policies or recovery timelines. It has verified none of them. Ask the platform what it supports and hold it to the written answer.
The one control worth the trouble
What a second factor does and does not stop
A second factor means access requires something beyond the password: a code from an authenticator application, a code sent to a registered device, or a hardware key. Its value is specific. It defeats the credential-reuse attack described above almost entirely, because knowing the password is no longer sufficient.
It does not defeat everything. A code entered into a convincing fake login page is a code the attacker now has, and codes sent by message can be intercepted if the phone number itself is compromised. An authenticator application is generally the stronger of the two common options, because the code is generated on the device rather than transmitted to it.
Whichever is available, generate and store the backup codes at the moment you enable it. A second factor with no recovery path is a lockout waiting for a lost phone, and recovering an account with a verified identity behind it is slower than most people expect.
Do it now
Setting up an account you can still reach in a year
Five steps, all of which are easier before there is a balance or a problem.
Use a unique password
The password on an account that holds money should exist nowhere else. Length matters more than symbol substitution, and a password manager removes the need to remember it.
If you have reused a password here, change it before doing anything else on this list.
Turn on a second factor and save the backup codes
Enable whatever the platform offers, preferring an authenticator application over message-delivered codes where both exist. Write the backup codes down and store them away from your password manager.
Codes stored in the same vault as the password protect you against nothing if that vault is what gets compromised.
Secure the recovery channel
The email address or phone number used for recovery is functionally part of the account. Give the email account its own unique password and its own second factor.
An account is only as strong as the weakest route into it, and the recovery route is usually that route.
Record your exact registered details
Note the registered name spelling, the email address used and the date you opened the account. A recovery conversation with a platform that must verify identity under the Act will turn on details like these.
Keep the note somewhere that does not depend on being logged in to read it.
Check your limits at the same time
While you are in the settings, set the deposit limit and time limit. Licensed platforms must provide self-exclusion, time limits and deposit limits under the Act, so the controls are there.
Security and limits live in the same part of an account for a practical reason: both are decisions best made while nothing urgent is happening.
If you are locked out
Three routes back in, in order of likely success
Work through these in sequence. Each one asks more of you than the last.
What each route requires
- 01 · A backup code
- The fastest route, and the reason to generate codes when enabling a second factor. It needs nothing from the platform's support team and no waiting.
- 02 · A password reset to a controlled address
- Works when you still hold the registered email or phone. This is why securing the recovery channel matters as much as securing the account itself.
- 03 · Identity-based recovery through support
- The slowest route, because the platform must satisfy its obligation to verify identity before moving access. Expect to supply the same documents used at verification, and expect the process to take time rather than minutes.
Choosing a second factor
How the common options differ
If a platform offers more than one, this is the basis for choosing. If it offers only one, use it.
None of these protects against entering a code into a fake login page. Check the address bar before typing a code anywhere.
| Method | How the code reaches you | Main weakness |
|---|---|---|
| Authenticator application | Generated on your device, never transmitted | Losing the device without backup codes saved |
| Code sent by message | Sent to your registered number | Exposed if the number itself is compromised or reassigned |
| Code sent by email | Sent to your registered address | Only as strong as the email account's own protection |
| Hardware key | Held physically by you | Cost, and platform support is uncommon in this category |
Reader questions
Access problems readers write in about
Short answers, with the limits of what this desk can tell you stated plainly.
I have lost my phone and my backup codes. What now?
You are on the identity-based recovery route, which means contacting the platform's support and expecting to prove who you are with the documents used at verification. A licensed platform cannot shortcut this, because verifying identity is an obligation the 2025 Act places on it.
Set expectations accordingly and keep a dated record of the correspondence. If recovery stalls unreasonably, licensed platforms must provide a grievance mechanism. The escalation page covers how to use it.
Should I let a browser save this password?
A dedicated password manager is preferable, because it keeps the credential behind its own authentication rather than behind whoever has the device unlocked. A browser store on a shared machine is effectively a shared password.
If a browser store is what you will actually use, it is better than reusing a memorable password across services.
The platform does not offer two-step verification. Is that a problem?
It is a genuine weakness, and worth weighing alongside the other checks on an operator. The 2025 Act requires identity and age verification and data protection of licensed platforms, but this desk is not going to characterise a specific security feature as legally mandated when it has not read that requirement in the Act.
Compensate with a long unique password and a well-protected recovery email, and apply the wider assessment method before committing funds.
Can someone else use my account if I am supervising?
No, and it puts your own access at risk. Licensed platforms must verify identity and age and must disallow access to minors, so an account used by someone other than the verified holder is a breach of the basis on which it was opened.
The consequence is not theoretical: it gives the platform a reason to freeze the account, and a withdrawal to a verified holder is exactly where that surfaces.
Does this desk know how long recovery takes at a given platform?
No. It has located no primary source for recovery timelines at any operator and will not estimate one.
Ask the platform for its stated process before you need it, and keep the answer with your account notes.
Related reading
Where to take this next
- Verification and withdrawalsWhat documents are compared, and why a name mismatch stalls a payment.
- Escalating a support problemWhat to log, and the tribunal the Act establishes for disputes.
- Comparing the mobile optionsWhat an app asks for on install, and what that tells you.
- The limits worth setting todayThe controls licensed platforms must provide, and what each one does.
Do these three now
The account tasks worth ten minutes
All three are cheap today and expensive after a lockout or a takeover.
- Is the password on this account used nowhere else, and is it stored in a manager rather than remembered?
- Is a second factor enabled, with backup codes written down and stored away from the password?
- Is the recovery email or phone number one you still control, and does it have its own protection?
Sources for the regulatory statements above
- Promotion and Regulation of Online Gaming Act, 2025The obligation on licensed platforms to verify identity and age and to disallow access to minors; mandatory self-exclusion, time limits and deposit limits; segregated user funds and refundability; grievance redressal and data protection; the Online Gaming Appellate Tribunal.
No operator's security features, session policies or recovery timelines appear above, because this desk has verified none of them. Ask the platform directly and keep the written answer with your account notes.